Captcha OCR

Do not call the API from a browser with a live key

2026-03-31 · Using the API

A key in frontend JavaScript is a key anyone can take. Call from your server.

The solve API is a server API. Put the key in the server environment and let your backend download the captcha, call Captcha OCR, and post the form.

A key inside a mobile app or a single-page app will be copied. Rotation becomes an incident instead of a config change.

The website's Try it box is server-side on purpose. The browser talks to the site, and the site talks to the API with the internal secret. Copy that shape.

SDK snippets that mention process.env or os.environ are showing the same rule.

Ready to call it? Start with the quickstart, the API guide, or pricing.

More in Using the API